Legal
Privacy policy
What information Solandra handles, why, who receives it, how long it is kept, and your choices.
Effective date: 16 September 2026
This policy explains what information Solandra handles, why, who receives it, how long we keep it, and your choices. Solandra is operated by Yashraj, an individual based in India, trading as Solandra. Contact for anything in this policy: contact@solandra.io.
1. Two kinds of people
Account holders and their teams use the dashboard. For your account, we decide how information is handled, as described here.
Visitors use an assistant on a customer's website. The customer decides what content the assistant answers from and how its team handles conversations; its own privacy notice applies. We process visitor conversations on the customer's behalf. If you are a visitor with a request, name the website so we can reach the right customer.
2. What we handle
- Account information: email address, sign-in records, organisation and project names, team memberships, roles and settings. Accounts are created by us after a conversation; there is no self-service registration.
- Connected website content: the URLs you connect, the text and titles of the pages we crawl, and the search representations built from them.
- Visitor conversations: questions, answers, human replies, source links, timestamps and a browser-generated visitor identifier. The widget does not ask visitors for a name or email; visitors may still type personal information into a message.
- Service information: request logs (paths, status codes, timings, request IDs, IP addresses used for rate limits) and error reports.
- Correspondence: what you send us by email or through a meeting booking.
3. Why we use it
To run the service you asked for: crawl your content, answer visitors, show gaps, notify your team about escalations and finished crawls, and keep accounts secure. To respond to you. To keep the service working and protect it from abuse. For account holders, the basis is the agreement between us and our legitimate interest in running the service; for visitor conversations, it is the customer's instructions. Where local law such as the EU GDPR or India's Digital Personal Data Protection Act requires a specific basis or consent, we rely on that.
We do not sell personal information and we do not use it for advertising.
4. AI processing
Questions, relevant excerpts of your content, and conversation context are sent to OpenAI to route the question, build search representations and generate the answer. Under OpenAI's API terms this data is not used to train their models. Private sources are excluded from public answers, but content that is used for an answer is processed by OpenAI like any other.
5. Who receives information
We use these providers to run Solandra. Each receives only what its job needs.
| Provider | Job | Location |
|---|---|---|
| Supabase | Authentication and the database | Mumbai, India (ap-south-1) |
| Qdrant Cloud | Search index of your content | Ireland (eu-west-1) |
| OpenAI | AI routing, embeddings and answers | United States |
| context.dev | Fetching the website pages you connect | United States |
| Resend | Sending notification emails | Ireland (eu-west-1) |
| Railway | Running the dashboard, widget, API and workers | Singapore, closest region to the database |
Information therefore moves between India, Ireland, the United States and Singapore. Each provider is bound by its own data processing terms, and we rely on those terms and their standard contractual protections for transfers. We keep this table current; existing customers are emailed before a new provider starts handling their data.
We also share information when the law requires it or to protect the service, and we may hand it to a successor if Solandra becomes a company or is transferred, under this same policy.
6. How long we keep it
- Account information: 30 days after the account is closed, then deleted.
- Connected content and its index: deleted when you delete the source, and in any case 30 days after account closure.
- Conversations, gaps and escalations: 12 months, or earlier if you delete the project. We will announce any change to this.
- Logs: up to 30 days.
- Backups: the database is backed up daily by Supabase; a deleted record can persist in a backup for up to 30 days before it expires.
- Correspondence: while we are in contact, and up to 24 months afterwards.
7. Cookies and browser storage
Dashboard: an HTTP-only sign-in cookie (one hour), a cookie remembering whether the sidebar is open (seven days) and a local-storage entry for the theme. No tracking cookies.
Widget: two local-storage entries, scoped to the widget key: a random visitor identifier and the current conversation id, so a returning visitor sees their conversation in the same browser. Starting a new conversation clears the conversation id; it does not delete server records.
This website: Google Analytics, which measures visits. In the EEA, UK and Switzerland it runs without cookies unless you consent; elsewhere it sets its usual cookies with IP addresses anonymised. The Cal.com booking page opens as a separate site with its own notice, and the demo widget on the home page uses the widget storage above. You can block cookies in your browser.
8. Your rights and choices
You can ask us to access, correct or delete personal information we hold about you, or to stop a particular use, by emailing contact@solandra.io. We answer within 30 days. Account holders can delete sources, projects and team members from the dashboard. If you are unhappy with our answer, you can complain to the data protection authority for your country; in India that is the Data Protection Board of India.
9. Age
Accounts are for people aged 18 or over. The service is not directed at children; a customer whose website serves children is responsible for its own compliance.
10. Security
Everything travels over HTTPS. Data is encrypted at rest by our providers. Sign-in is handled by Supabase Auth and the dashboard keeps its session in an HTTP-only cookie. The founder is the only person with administrative access, protected by two-factor authentication. More on the data security page.
11. Changes and contact
We will update this policy as the service and the law change; material changes are emailed to account holders. Questions, requests and complaints: contact@solandra.io.